Type Confusion Vulnerability in Magma by Cellular Security
CVE-2024-24421
9.8CRITICAL
What is CVE-2024-24421?
A type confusion vulnerability exists in the nas_message_decode function of Magma versions 1.8.0 and earlier. This flaw can be exploited by attackers through crafted NAS packets, potentially leading to arbitrary code execution or resulting in Denial of Service (DoS) attacks. It is crucial for users to update to version 1.9 or later to mitigate this risk.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
